Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

WpEvently — Vulnerabilities & Security Advisories 18

All 18 CVE vulnerabilities found in WpEvently, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for the product WpEvently, a WordPress plugin for managing events, focusing primarily on cross-site scripting and access control weaknesses. It collects security advisories and defect reports associated with this specific software component, covering the full historical range of known issues from initial release through the most recent updates. Visitors can use this resource to track vendor-published advisories, understand the specific class of weaknesses affecting the codebase, and review the complete vulnerability history for the product. The data helps security professionals identify recurring patterns in the software, such as recurring input validation failures or misconfigured permissions, without needing to consult external databases for individual entries. This aggregation provides a centralized view of the product's security posture over time.

Vendor: magepeopleteam

CVE ID Title CVSS Severity Published
CVE-2026-81802 WordPress WpEvently plugin <= 5.6.0 - Insecure Direct Object References (IDOR) vulnerability CWE-639 6.5 Medium 2026-09-08
CVE-2026-81761 WordPress WpEvently plugin <= 5.5.0 - Broken Access Control vulnerability CWE-862 4.3 Medium 2026-08-28
CVE-2026-81759 WordPress WpEvently plugin <= 5.5.0 - Broken Access Control vulnerability CWE-862 5.4 Medium 2026-08-28
CVE-2026-45441 WordPress WpEvently plugin <= 5.3.3 - Other Vulnerability Type vulnerability CWE-1284 7.5 High 2026-06-15
CVE-2024-32110 WordPress Event Manager and Tickets Selling Plugin for WooCommerce plugin <= 4.1.2 - Cross Site Request Forgery (CSRF) vulnerability CWE-352 4.3 Medium 2026-06-11
CVE-2026-25361 WordPress WpEvently plugin <= 5.1.4 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2026-03-25
CVE-2026-32354 WordPress WpEvently plugin < 5.1.9 - Sensitive Data Exposure vulnerability CWE-201 5.3 Medium 2026-03-13
CVE-2026-23549 WordPress WpEvently plugin <= 5.1.1 - PHP Object Injection vulnerability CWE-502 9.8 Critical 2026-02-19
CVE-2026-24954 WordPress WpEvently plugin <= 5.0.8 - Deserialization of untrusted data vulnerability CWE-502 8.8 High 2026-02-03
CVE-2026-24942 WordPress WpEvently plugin <= 5.1.1 - Cross Site Request Forgery (CSRF) vulnerability CWE-352 4.3 Medium 2026-02-03
CVE-2025-66083 WordPress WpEvently plugin <= 5.0.4 - Broken Access Control vulnerability CWE-862 5.3 Medium 2025-11-21
CVE-2025-66082 WordPress WpEvently plugin <= 5.0.4 - Broken Access Control vulnerability CWE-862 5.3 Medium 2025-11-21
CVE-2025-54742 WordPress WpEvently Plugin <= 4.4.8 - PHP Object Injection Vulnerability CWE-502 8.8 High 2025-08-28
CVE-2025-54705 WordPress WpEvently plugin <= 4.4.6 - Broken Access Control vulnerability CWE-862 4.3 Medium 2025-08-14
CVE-2025-32145 WordPress WpEvently plugin <= 4.3.6 - PHP Object Injection vulnerability CWE-502 8.8 High 2025-04-10
CVE-2025-30895 WordPress WpEvently Plugin <= 4.2.9 - PHP Object Injection vulnerability CWE-22 7.5 High 2025-03-27
CVE-2025-30887 WordPress WpEvently Plugin <= 4.2.9 - Broken Access Control vulnerability CWE-862 5.3 Medium 2025-03-27
CVE-2024-49703 WordPress WpEvently plugin <= 4.2.5 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2024-10-24

All 18 known CVE vulnerabilities affecting WpEvently with full Chinese analysis, references, and POCs where available.